US2026058820A1PendingUtilityA1

Authentication methods

Assignee: GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTDPriority: May 6, 2023Filed: Nov 3, 2025Published: Feb 26, 2026
Est. expiryMay 6, 2043(~16.8 yrs left)· nominal 20-yr term from priority
Inventors:GAN LU
H04W 12/069H04W 12/106H04W 12/009H04L 9/0869H04L 9/085H04L 9/14H04L 9/3242
74
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An authentication method includes: receiving, by a second device, a second message from a first device, the second message carrying a MAC and an authentication parameter; calculating, by the second device, a verification MAC based on the authentication parameter and a root key, the root key being a key shared between the second device and a core network side device; completing, by the second device, authentication of the core network side device in a case where the verification MAC is the same as the MAC.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An authentication method, comprising:
 receiving, by a second device, a second message from a first device, the second message carrying a MAC and an authentication parameter;   calculating, by the second device, a verification MAC based on the authentication parameter and a root key, the root key being a key shared between the second device and a core network side device;   completing, by the second device, authentication of the core network side device in a case where the verification MAC is the same as the MAC.   
     
     
         2 . The method according to  claim 1 , wherein the authentication parameter comprises one of an anonymous key and a first random number. 
     
     
         3 . The method according to  claim 2 , wherein calculating, by the second device, the verification MAC based on the authentication parameter and the root key, comprises one of:
 calculating, by the second device using a first calculation manner, the verification MAC based on the anonymous key and the root key;   calculating, by the second device, the anonymous key based on an exclusive OR (XOR) of the first random number and the root key, and calculating, by the second device using the first calculation manner, the verification MAC based on the anonymous key and the root key;   calculating, by the second device, the first random number based on an XOR of the anonymous key and the root key, and calculating, by the second device using the first calculation manner, the verification MAC based on the first random number and the root key; or   calculating, by the second device using the first calculation manner, the verification MAC based on the first random number and the root key.   
     
     
         4 . The method according to  claim 3 , wherein calculating, by the second device using the first calculation manner, the verification MAC based on the anonymous key and the root key, comprises: calculating, by the second device using the first calculation manner, the verification MAC based on service parameters, the anonymous key and the root key; and/or,
 calculating, by the second device using the first calculation manner, the verification MAC based on the first random number and the root key, comprises: calculating, by the second device using the first calculation manner, the verification MAC based on the service parameters, the first random number and the root key.   
     
     
         5 . The method according to  claim 3 , wherein the method further comprises:
 transmitting, by the second device, a third message to the first device, the third message being used to indicate the second device has completed the authentication of the core network side device.   
     
     
         6 . The method according to  claim 5 , wherein the third message carries at least one of:
 a first RES, the first RES being used for the core network side device to perform authentication of the second device; or   a second RES, the second RES being used for the first device to perform authentication of the second device.   
     
     
         7 . The method according to  claim 4 , wherein the second message further carries the service parameters, and the service parameters comprise at least one of: a type parameter for indicating an ambient Internet of Things (AIoT) service type, an identifier of a server with an AIoT service function, or a type parameter for indicating an AIoT authentication type. 
     
     
         8 . The method according to  claim 1 , wherein the method further comprises:
 transmitting, by the second device, an authentication request to the first device, the authentication request carrying an identifier of the second device.   
     
     
         9 . The method according to  claim 3 , wherein the first calculation manner comprises one of a second authentication function, a hash algorithm, an advanced encryption standard (AES), ACSON, snow third generation (SNOW 3G), and ZUChongzhi (ZUC). 
     
     
         10 . The method according to  claim 1 , wherein the core network side device comprises one or more core network devices or authentication servers; the second device is an AIoT device; the first device comprises at least one of a terminal device, an access network device, an authenticator, or a first core network device. 
     
     
         11 . An authentication method, comprising:
 receiving, by a second device, a second message from a first device, the second message carrying an authentication parameter;   calculating, by the second device, a first RES based on the authentication parameter and a root key, the root key being a key shared between the second device and a core network side device;   transmitting, by the second device, a third message to the first device, the third message carrying the first RES, and the first RES being used for the core network side device to perform authentication of the second device.   
     
     
         12 . The method according to  claim 11 , wherein the authentication parameter comprises one of an anonymous key and a first random number; and calculating, by the second device, the first RES based on the authentication parameter and the root key, comprises one of:
 calculating, by the second device using a first calculation manner, the first RES based on the first random number and the root key; or   calculating, by the second device using the first calculation manner, the first RES based on the anonymous key and the root key.   
     
     
         13 . The method according to  claim 12 , wherein calculating, by the second device using the first calculation manner, the first RES based on the first random number and the root key, comprises: calculating, by the second device using the first calculation manner, the first RES based on service parameters, the first random number and the root key; and/or,
 calculating, by the second device using the first calculation manner, the first RES based on the anonymous key and the root key, comprises: calculating, by the second device using the first calculation manner, the first RES based on the service parameters, the anonymous key and the root key.   
     
     
         14 . The method according to  claim 13 , the second message further carries the service parameters, and the service parameters comprise at least one of: a type parameter for indicating an ambient Internet of Things (AIoT) service type, an identifier of a server with an AIoT service function, or a type parameter for indicating an AIoT authentication type. 
     
     
         15 . The method according to  claim 11 , wherein the third message further carries a second RES, and the second RES is used for the first device to perform authentication of the second device; and the method further comprises one of:
 calculating, by the second device using a first calculation manner, the second RES based on an anonymous key and a first key, the first key being related to the first device;   calculating, by the second device using the first calculation manner, the second RES based on a first random number and the first key; or   calculating, by the second device using the first calculation manner, the second RES based on the first RES and the first key.   
     
     
         16 . The method according to  claim 10 , wherein the core network side device comprises one or more core network devices or authentication servers; the second device is an AIoT device; the first device comprises at least one of a terminal device, an access network device, an authenticator, or a first core network device. 
     
     
         17 . An authentication method, comprising:
 transmitting, by a first network device, a first message to a first device, the first message carrying an authentication parameter and an identifier of a second device;   receiving, by the first network device, a fourth message from the first device, the fourth message carrying a first RES, wherein the first RES is obtained by the second device based on the authentication parameter and a root key, and the root key is a key shared between the second device and a core network side device; and   determining, by the first network device, that authentication of the second device succeeds in a case where the first RES is the same as a first verification RES.   
     
     
         18 . The method according to  claim 17 , wherein the authentication parameter comprises one of an anonymous key and a first random number. 
     
     
         19 . The method according to  claim 18 , wherein the method further comprises one of:
 receiving, by the first network device, the authentication parameter and the first verification RES that are transmitted by a second network device; or   calculating, by the first network device using a first calculation manner, the first verification RES based on the root key and the authentication parameter.   
     
     
         20 . The method according to  claim 19 , wherein the core network side device comprises one or more core network devices or authentication servers; the second device is an ambient Internet of Things (AIOT) device; the first device comprises at least one of a terminal device, an access network device, an authenticator, or a first core network device; the first network device is an authentication server function (AUSF) or an authentication server; the second network device comprises at least one of a user data management (UDM), or an authentication credential repository and processing function (ARPF).

Join the waitlist — get patent alerts

Track US2026058820A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.